Case Amplify
Privacy, Security & Compliance
Privacy, Security & Compliance
The trust of our customers and their clients is of the highest priority at Case Amplify. We maintain HIPAA-compliant data storage and processing protocols for all data captured and shared through our platform, and our processes and systems have been audited by ConstellationGRC, validating our compliance with HIPAA and SOC 2 Type II standards.
Internal Personnel Security
All Case Amplify employees are required to:
- Undergo background checks before being hired
- Complete annual training on security awareness, HIPAA, privacy, and information classification
Secure Development Lifecycle
- All software changes are reviewed for compliance and security risks
- Separation of duties is maintained across the development lifecycle
- All changes require documented approval before deployment
- Case Amplify practices infrastructure-as-code; all infrastructure changes are reviewed before deployment
- All engineers complete secure development practices training
- Case Amplify’s code and the underlying cloud infrastructure and networking are subject to automated security scanning
Cloud Hosting and Availability
- All hosting services and data is stored and processed within Microsoft’s Azure secure data centers
- Case Amplify has a HIPAA-compliant Business Associate Agreement with Microsoft
- Case Amplify leverages Azure’s high-availability infrastructure to ensure the data is always accessible
Confidentiality and Data Encryption
- All data is encrypted at rest and in transit using industry standard encryption schemes
- All access to patient data is restricted to user granted access by the provider’s organization
Vendor Management
- All vendors who may process patient information are required to be HIPAA compliant and have BAAs in place with Case Amplify
- Case Amplify regularly reviews vendor security practices to ensure continued high standards
Artificial Intelligence
- Case Amplify uses AI within HIPAA-compliant data handling and processing workflows. AI models do not retain customer data, and protected health information is never used for AI training purposes.
- Protected health information is never used for AI training purposes
Client Information
- Client information is encrypted at-rest and in-transit
- Client recordings are temporarily saved in a secure and HIPAA-compliant manner until note summaries and quality checks are complete, and then they are automatically deleted
Auditability
- Audit logs are maintained at the infrastructure, application, and source code levels
- Audit log records are created each time a client’s case data is viewed and for any changes to a client’s case